Skip to content

Publish techdocs via OIDC instead of static AWS credentials - #125

Merged
psi merged 3 commits into
masterfrom
oidc-techdocs
Sep 3, 2026
Merged

psi merged 3 commits into
masterfrom
oidc-techdocs

Conversation

@psi

@psi psi commented Aug 11, 2026 •

Copy link
Copy Markdown
Member

Summary

Migrates this repo's techdocs publishing off the static TRUSS_AWS_ACCESS_KEY_ID / TRUSS_AWS_SECRET_ACCESS_KEY org secrets and onto GitHub OIDC role assumption.

The shared Bridge Backstage Techdocs action (get-bridge/developer_portal/.github/actions/techdocs) now assumes the github-truss IAM role via OIDC by default (see get-bridge/developer_portal#105). Consumers only need to:

  1. Grant permissions: id-token: write on the job.
  2. Stop passing the aws_access_key_id / aws_secret_access_key inputs.

No AWS credentials are handled by this workflow anymore.

⚠️ Merge ordering

This depends on get-bridge/developer_portal#105 being merged first. This workflow tracks the action at ref: master, and until #105 lands the action still marks those credential inputs as required. Please merge #105 before merging this PR.

Reference migration pattern: get-bridge/bridge-instilled@a3545c8.

CI build fixes

This PR also fixes pre-existing CI failures unrelated to the OIDC change:

  • RuboCop Style/HashAsLastArrayItem — Wrapped implicit hashes inside array literals with explicit {} braces in destinations.rb and dispatches.rb. RuboCop 1.89.0 (installed in CI) flags the implicit form.
  • Ruby head bundler compatibility — Widened the bundler dev dependency from ~> 2.0 to >= 2.0. Ruby head ships Bundler 4.x, which the pessimistic constraint rejected.
  • Removed deprecated macos-13 runner — GitHub deprecated macOS-13 runners; jobs hung for 24 hours before being cancelled. The workflow still tests on macos-latest and macos-latest-large.

Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com

The techdocs workflow no longer passes TRUSS_AWS_ACCESS_KEY_ID /
TRUSS_AWS_SECRET_ACCESS_KEY to the Bridge Backstage Techdocs action. The
action now assumes the github-truss IAM role via GitHub OIDC by default, so
the workflow only needs to grant id-token: write.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
jamesh-gomo
jamesh-gomo previously approved these changes Aug 17, 2026

@jamesh-gomo jamesh-gomo left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @psi ,

The change looks good. I don't think we can't really test this until it's merged into Master - so keeping an eye on Spinnaker staging and edge env's after merging is probably the safest way to confirm it's working

- Fix RuboCop Style/HashAsLastArrayItem offenses in destinations.rb
  and dispatches.rb by wrapping implicit hashes in explicit braces
- Widen bundler dev dependency from ~> 2.0 to >= 2.0 so Ruby head
  (which ships Bundler 4.x) can resolve dependencies
- Remove deprecated macos-13 runner from CI matrix

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

@jamesh-gomo jamesh-gomo left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good ✅

@psi
psi merged commit fd31d81 into master Sep 3, 2026
21 checks passed
@psi
psi deleted the oidc-techdocs branch September 3, 2026 13:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants